13 Penetration Testing jobs in Singapore

Security Engineer

Singapore, Singapore AVENSYS CONSULTING PTE. LTD.

Job Viewed

Tap Again To Close

Job Description

Roles & Responsibilities

Avensys is a reputed global IT professional services company headquartered in Singapore. Our service spectrum includes enterprise solution consulting, business intelligence, business process automation and managed services. Given our decade of success we have evolved to become one of the top trusted providers in Singapore and service a client base across banking and financial services, insurance, information technology, healthcare, retail, and supply chain.

We are currently looking to hire Security Engineer. This is an exciting opportunity to expand your skill set, achieve job satisfaction and work-life balance. More details as below.

Roles and Responsibilities

The Cyber Security consultant will design, implement, test, document, and hand over security solutions with a focus on Security by Design principles. The role includes deploying and managing virtual and physical firewalls, forward and reverse proxy, network security policy management and automation, endpoint security, vulnerability management and zero trust network access solution across AWS and Azure environments. Additionally, the engineer will use Terraform and other IaC tools to automate security infrastructure, conduct various security tests (SSAT, OSAT, IAT, UAT), and perform system hardening to safeguard systems against vulnerabilities.

· Security by Design: Integrate security into all stages of system design and development. Perform risk assessments and threat modelling when required.

· Implementation & Automation: Deploy firewall, proxy, endpoint and network security solutions. Automate security infrastructure with Terraform and maintain consistent security deployments.

· Testing & Hardening: Conduct System Security Acceptance Testing (SSAT), Operational Security Acceptance Testing (OSAT), Integration Acceptance Testing (IAT), User Acceptance Testing (UAT), and system hardening to ensure secure configurations.

Documentation & Handover: Create detailed documentation for security controls and processes. Provide training and handover to the operations team, with operational guides for security management.

Develop, architect, and deploy network firewall appliances from leading vendors such as Palo Alto Networks, Check Point Software Technologies, and Fortinet, ensuring robust perimeter security and threat prevention tailored to organizational needs.

Design and implement forward and reverse proxy solutions utilizing SkyHigh Secure Web Gateway, enhancing web traffic security, content filtering, and data loss prevention across enterprise networks.

Architect and integrate network security policy management solutions using AlgoSec, automating policy orchestration, optimizing firewall rules, and ensuring compliance across hybrid network environments.

Engineer and deploy Zero Trust security architectures leveraging Zscaler and Palo Alto Networks solutions, enforcing strict identity verification and least-privilege access controls to secure user and application interactions.

· Security by Design: Integrate security into all stages of system design and development. Perform risk assessments and threat modelling when required.

· Implementation & Automation: Deploy firewall, proxy, endpoint and network security solutions. Automate security infrastructure with Terraform and maintain consistent security deployments.

· Testing & Hardening: Conduct System Security Acceptance Testing (SSAT), Operational Security Acceptance Testing (OSAT), Integration Acceptance Testing (IAT), User Acceptance Testing (UAT), and system hardening to ensure secure configurations.

Documentation & Handover: Create detailed documentation for security controls and processes. Provide training and handover to the operations team, with operational guides for security management.

WHAT'S ON OFFER

You will be remunerated with an excellent base salary and entitled to attractive company benefits. Additionally, you will get the opportunity to enjoy a fun and collaborative work environment, alongside a strong career progression.

To submit your application, please apply online or email your UPDATED CV in Microsoft Word format to Your interest will be treated with strict confidentiality.

CONSULTANT DETAILS

Consultant Name: Deepa Shivakoti

Reg No: R1765546

Avensys Consulting Pte Ltd

EA Licence 12C5759

Privacy Statement: Data collected will be used for recruitment purposes only. Personal data provided will be used strictly in accordance with the relevant data protection law and Avensys' privacy policy .

Tell employers what skills you have

Managed Services
Process Automation
Azure
Vulnerability Management
Cyber Security
Architect
Information Technology
Security Management
Reverse Proxy
Hardening
Prevention
Microsoft Word
Orchestration
Loss Prevention
Acceptance Testing
Network Security
This advertiser has chosen not to accept applicants from your region.

Job No Longer Available

This position is no longer listed on WhatJobs. The employer may be reviewing applications, filled the role, or has removed the listing.

However, we have similar jobs available for you below.

Penetration Testing Specialist

Singapore, Singapore STACKTECH PTE. LTD.

Posted today

Job Viewed

Tap Again To Close

Job Description

About the Role
As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization's cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.
Key Responsibility
  • Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
  • Propose measures to ensure that identified vulnerabilities are addressed.
  • Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
  • Simulate cyber attacks to evaluate defensive measures and improve security posture.
Requirements
  • Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
  • Experience conducting secure code review.
  • Degree in computer science/computer engineering/information security or equivalent.
  • Working knowledge of all aspects of information security is essential.
  • Familiarity with systems and operational architecture of large internet companies or online business models.
  • Good communication (spoken and written) skills, able to work independently and as a team.
  • Certifications from either GIAC/Offensive Security/CREST required.
  • Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
  • Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.
渗透测试专家
关于职位
作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统,应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性,确保合规性并降低运营风险,直接支持审计目标。
主要职责
  • 对应用程序,数据库,系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
  • 提出措施,确保已识别的漏洞得到解决。
  • 与IT,风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
  • 模拟网络攻击,评估防御措施并提升安全态势。
职位要求
  • 至少5年Web应用程序,移动应用程序,API,网络,数据库和负载测试的渗透测试经。
  • 具备安全代码审查经验。
  • 计算机科学/计算机工程/信息安全或同等学历。
  • 具备信息安全各方面的工作知识。
  • 熟悉大型互联网公司或在线商业模式的系统和运营架构。
  • 良好的沟通能力,能够独立工作和团队合作。
  • 需持有GIAC/Offensive Security/CREST认证。
  • 具有 Kali Linux,Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
  • 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
This advertiser has chosen not to accept applicants from your region.

Penetration Testing Specialist

Singapore, Singapore STACKTECH PTE. LTD.

Posted today

Job Viewed

Tap Again To Close

Job Description

Roles & Responsibilities

About the Role

As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization's cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.

Key Responsibility

  • Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
  • Propose measures to ensure that identified vulnerabilities are addressed.
  • Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
  • Simulate cyber attacks to evaluate defensive measures and improve security posture.

Requirements

  • Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
  • Experience conducting secure code review.
  • Degree in computer science/computer engineering/information security or equivalent.
  • Working knowledge of all aspects of information security is essential.
  • Familiarity with systems and operational architecture of large internet companies or online business models.
  • Good communication (spoken and written) skills, able to work independently and as a team.
  • Certifications from either GIAC/Offensive Security/CREST required.
  • Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
  • Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.

渗透测试专家

关于职位

作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统、应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性、确保合规性并降低运营风险,直接支持审计目标。

主要职责

  • 对应用程序、数据库、系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
  • 提出措施,确保已识别的漏洞得到解决。
  • 与IT、风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
  • 模拟网络攻击,评估防御措施并提升安全态势。

职位要求

  • 至少5年Web应用程序、移动应用程序、API、网络、数据库和负载测试的渗透测试经。
  • 具备安全代码审查经验。
  • 计算机科学/计算机工程/信息安全或同等学历。
  • 具备信息安全各方面的工作知识。
  • 熟悉大型互联网公司或在线商业模式的系统和运营架构。
  • 良好的沟通能力,能够独立工作和团队合作。
  • 需持有GIAC/Offensive Security/CREST认证。
  • 具有 Kali Linux、Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
  • 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
Tell employers what skills you have

Information Security
Transaction Processing
Remediation
Oracle SQL
Mainframe
Assessor
Penetration Testing
Mobile Applications
DB2
Web Applications
Kali Linux
Small Business
Mortgage Banking
Databases
Field Work
Audit
This advertiser has chosen not to accept applicants from your region.

Penetration Testing Consultant

048545 $5500 Monthly SWARMNETICS PTE. LTD.

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

Job Summary:

We are seeking a highly skilled and experienced penetration testing Consultant. In this role, you will be responsible for executing technical security assessments.

Responsibilities:

· Perform technical security assessment engagements for clients including penetration testing, host configuration reviews, secure code reviews, etc

· Contribute to the development and enhancement of assessment methodologies

· Participate in the development of new services

Requirements:

· Bachelor's degree in computer science, cybersecurity, or related field

· Professional certifications: OSCP, CRT

· 3+ years of experience in penetration testing or a related field

· Knowledge of penetration testing methodologies, tools and frameworks

· Experience with network (wired and wireless) and application (web, mobile, thick) security testing

Viewed Favorably:

· Credited with CVEs

· Participates in bug bounty programs

· Organizes or participates in CTFs

· Delivers technical research at security conferences

This advertiser has chosen not to accept applicants from your region.

Penetration Testing Specialist

188968 $11000 Monthly STACKTECH PTE. LTD.

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

About the Role

As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization’s cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.


Key Responsibility

  • Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
  • Propose measures to ensure that identified vulnerabilities are addressed.
  • Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
  • Simulate cyber attacks to evaluate defensive measures and improve security posture.

Requirements

  • Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
  • Experience conducting secure code review.
  • Degree in computer science/computer engineering/information security or equivalent.
  • Working knowledge of all aspects of information security is essential.
  • Familiarity with systems and operational architecture of large internet companies or online business models.
  • Good communication (spoken and written) skills, able to work independently and as a team.
  • Certifications from either GIAC/Offensive Security/CREST required.
  • Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
  • Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.

渗透测试专家


关于职位

作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统、应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性、确保合规性并降低运营风险,直接支持审计目标。


主要职责

  • 对应用程序、数据库、系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
  • 提出措施,确保已识别的漏洞得到解决。
  • 与IT、风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
  • 模拟网络攻击,评估防御措施并提升安全态势。

职位要求

  • 至少5年Web应用程序、移动应用程序、API、网络、数据库和负载测试的渗透测试经。
  • 具备安全代码审查经验。
  • 计算机科学/计算机工程/信息安全或同等学历。
  • 具备信息安全各方面的工作知识。
  • 熟悉大型互联网公司或在线商业模式的系统和运营架构。
  • 良好的沟通能力,能够独立工作和团队合作。
  • 需持有GIAC/Offensive Security/CREST认证。
  • 具有 Kali Linux、Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
  • 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
This advertiser has chosen not to accept applicants from your region.

Security Consultant (Penetration Testing)

368242 $7500 Monthly VANTAGE POINT SECURITY PTE. LTD.

Posted 10 days ago

Job Viewed

Tap Again To Close

Job Description

Role Purpose:

The Security Consultant delivers penetration testing & offensive security projects to ensure a successful

outcome that at least meets or exceeds the expectations of our clients.

Role Outcomes:
  • The customer recognises you as a subject matter expert and they have confidence in the comprehensiveness of the testing methodology and the accuracy of the results.
  • The client has prepared the testing environment prior to the project start date so that the engagement is executed smoothly and without delay.
  • Penetration testing projects are delivered efficiently and on schedule.
  • The quality of the Penetration Testing Report by ensuring it has been peer reviewed and approved for release to the client.
  • All client data is managed in strict accordance with Vantage Point Security data security and protection policies throughout the project.
This advertiser has chosen not to accept applicants from your region.

Penetration Tester - Cloud VAPT (Vulnerability Assessment and Penetration Testing)

$9000 Monthly KRIS INFOTECH PTE. LTD.

Posted 10 days ago

Job Viewed

Tap Again To Close

Job Description

Job Description:

  • Need to have experience good experience in the specific Penetration Testing.
  • Experience in Vulnerability Assessment, and Offensive Security.
  • Proficient in network, web application, and API testing.
  • Good communication skills.
  • Mandatory to have OSCP Certification.

Also require certification in :

  • AWS Certified Security Specialization
  • AWS Certified Solutions Architect – Associate
  • AWS Certified Solutions Architect – Professional
  • AWS Certified Cloud Practitioner.


This advertiser has chosen not to accept applicants from your region.

Security Testing Specialist

Singapore, Singapore OCBC

Posted 7 days ago

Job Viewed

Tap Again To Close

Job Description

Join to apply for the Security Testing Specialist role at OCBC .

Who We Are
As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. We provide support, services, solutions, and career paths tailored to our clients’ needs.

Today, we’re on a journey of transformation, leveraging technology and creativity to become a future-ready learning organisation. Our strategic ambition is to be Asia’s leading financial services partner for a sustainable future.

We invite you to build the bank of the future, innovate in financial services, work in supportive teams, and build lasting value in your community. Enjoy a vibrant, future-ready career with us.

Your Opportunity Starts Here.

Why Join

Protecting our customers' assets and data is central to our mission. As a Security Testing Specialist, you'll play a key role in safeguarding our systems from cyber threats, shaping the future of cybersecurity in finance.

How you succeed

Stay ahead of emerging threats, collaborate with engineering teams to identify and mitigate risks, and develop strategies to enhance cybersecurity.

What you do

  • Perform application penetration testing on web-based applications, APIs
  • Conduct mobile application penetration testing across platforms
  • Perform network penetration testing
  • Exploit vulnerabilities to assess security risks
  • Document security issues and recommend mitigations
  • Research latest security topics and attack vectors
  • Conduct compliance testing per standards like MAS TRMG
  • Perform secure code reviews when needed
  • Conduct thick client penetration testing as required
Who you are
  • Minimum 3 years of hands-on penetration testing experience
  • Experience with secure code review
  • Degree in computer science, security, or related field
  • Knowledge of all aspects of information security
  • Familiarity with MAS TRMG and regulatory requirements
  • Strong communication skills, able to work independently and in teams
  • Certifications from GIAC, Offensive Security, CREST
  • Hands-on experience with Kali Linux, Burp Suite, Tenable, and similar tools
  • Experience conducting penetration testing for banks in Singapore preferred
  • Experience with legacy systems review is a plus
#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Penetration testing Jobs in Singapore !

Senior Cyber Security Testing Specialist

Singapore, Singapore Singtel Group

Posted 6 days ago

Job Viewed

Tap Again To Close

Job Description

Select how often (in days) to receive an alert:

Senior Cyber Security Testing Specialist

Seeking a highly skilled and motivated Senior Cyber Security Testing Specialist who is skilled in application and infrastructure penetration testing, vulnerability assessment and secure code review to conduct, guide and review the work of external and cross function team security testers. In this role, you will be responsible for assessing and enhancing the security posture of the organisation’s critical applications and infrastructure through comprehensive testing, vulnerability assessment, and penetration testing techniques. Your expertise will play a crucial role in identifying security vulnerabilities and recommending risk mitigation strategies to different senior stakeholders

Make An Impact By

  • Coordinate and Oversee Penetration Testing & Vulnerability Assessment Engagements:
    • Manage and coordinate penetration testing and vulnerability assessment engagements with external vendors, ensuring effective communication and collaboration between internal stakeholders and vendors.
    • Work closely with Domain security champions to review and tailor the scope, rules of engagement, testing methodologies, and reporting for external penetration tests and vulnerability assessments.
    • Collaborate with cross-functional teams to provide guidance on Singtel's security standards, recommend best practices, and advise on effective remediation strategies.
    • Review penetration testing reports, prioritize identified vulnerabilities, and coordinate efforts to address them in a timely manner.
    • Track and report on the progress and outcomes of penetration testing and vulnerability assessments, ensuring that all findings are addressed appropriately.
  • Maintenance of tools and Conduct Various Penetration Tests:
    • Perform different types of penetration testing (e.g., AI models, application, API, Infrastructure, etc.) following recognized methodologies, including OWASP and Singtel’s internal standards, utilizing both manual and automated testing methods, as needed.
    • Maintain and configure the tests required of automated testing tools to support black box and white box testing, and ensure alignment with latest industry test requirements e.g. OWASP, covering all forms of technologies e.g. Cloud Apps, On-prem Apps, COTS products, In-house developed Apps, AI models, APIs, OS, DB, VM, Network devices, etc.
    • Identify gaps in automated testing tools and propose new tooling required to augment testing program as needed
  • Bug Bounty Program Management:
    • Oversee and manage the bug bounty program and associated platforms for identifying and addressing reported vulnerabilities.
    • Validate/ triage the reported vulnerabilities, assess their impact on Singtel’s systems, and collaborate with relevant stakeholders to prioritize and remediate the issues.
    • Track and report on findings and outcomes from the bug bounty program to ensure timely resolution.
    • Develop engaging programs to boost the visibility and popularity of Singtel's bug bounty program.
  • Manage and conduct secure code reviews using scanning tools and techniques to identify security weaknesses in software code.
  • Analyze the results from code scans and work closely with development teams to implement necessary security fixes.
  • Assist in the creation and implementation of secure coding practices across the organization.
  • Vulnerability Retesting and Documentation:
    • Retest security vulnerabilities arising from various sources e.g. Bug Bounty, Penetration testing, etc. after remediation and update reports with the latest results and outcomes.
    • Develop and maintain comprehensive documentation for all vulnerability assessments, secured code reviews and penetration tests, including detailed findings, methodologies, and recommendations for improvements etc.
  • Stay Current with Security Trends and Threats:
    • Continuously monitor the latest security trends, emerging vulnerabilities, and attack techniques to ensure that security testing methodologies and tools remain up-to-date and effective.

Skills for Success:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Attained OSCP or CREST.
  • At least 5 years of experience working in Cyber and Information security field
  • Solid experience in application security testing, vulnerability assessment, secure code review and penetration testing.
  • Proficiency in performing AI models, API and application security testing using manual techniques, as well as utilizing runtime vulnerability testing tools and/or code review tools.
  • Strong understanding of OWASP Top 10, CWE/SANS Top 25, and other common vulnerability frameworks.
  • Out of which, at least 3 years experience in delivering various AI model, API, application, infrastructure penetration testing, vulnerability assessment and secure code review.
  • Proficiency in performing AI model, API and application security assessment using manual techniques.
  • Proficient in using and managing various security tools and products like Fortify, AppScan, Webinspect, Burp Suite, Nessus, Guardrails AI, Giskard, Moonshot, Deepcheck, Evidently, Pyrit, Adversarial Robustness Toolbox (ART), PyRIT, etc.

Rewards that Go Beyond

  • Full suite of health and wellness benefits
  • Ongoing training and development programs
  • Internal mobility opportunities

Are you ready to say hello to BIG Possibilities?

Take the leap with Singtel to unlock new opportunities and accelerate your growth. Apply now and start your empowering career!

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Senior Cyber Security Testing Specialist

Singapore, Singapore Singtel Group

Posted 6 days ago

Job Viewed

Tap Again To Close

Job Description

Senior Cyber Security Testing Specialist

Seeking a highly skilled and motivated Senior Cyber Security Testing Specialist who is skilled in application and infrastructure penetration testing, vulnerability assessment and secure code review to conduct, guide and review the work of external and cross function team security testers. In this role, you will be responsible for assessing and enhancing the security posture of the organisation’s critical applications and infrastructure through comprehensive testing, vulnerability assessment, and penetration testing techniques. Your expertise will play a crucial role in identifying security vulnerabilities and recommending risk mitigation strategies to different senior stakeholders.

Make An Impact By

  • Coordinate and Oversee Penetration Testing & Vulnerability Assessment Engagements:
    • Manage and coordinate penetration testing and vulnerability assessment engagements with external vendors, ensuring effective communication and collaboration between internal stakeholders and vendors.
    • Work closely with Domain security champions to review and tailor the scope, rules of engagement, testing methodologies, and reporting for external penetration tests and vulnerability assessments.
    • Collaborate with cross-functional teams to provide guidance on Singtel's security standards, recommend best practices, and advise on effective remediation strategies.
    • Review penetration testing reports, prioritize identified vulnerabilities, and coordinate efforts to address them in a timely manner.
    • Track and report on the progress and outcomes of penetration testing and vulnerability assessments, ensuring that all findings are addressed appropriately.
  • Maintenance of tools and Conduct Various Penetration Tests:
    • Perform different types of penetration testing (e.g., AI models, application, API, Infrastructure, etc.) following recognized methodologies, including OWASP and Singtel’s internal standards, utilizing both manual and automated testing methods, as needed.
    • Maintain and configure the tests required of automated testing tools to support black box and white box testing, and ensure alignment with latest industry test requirements e.g. OWASP, covering all forms of technologies e.g. Cloud Apps, On-prem Apps, COTS products, In-house developed Apps, AI models, APIs, OS, DB, VM, Network devices, etc.
    • Identify gaps in automated testing tools and propose new tooling required to augment testing program as needed.
  • Bug Bounty Program Management:
    • Oversee and manage the bug bounty program and associated platforms for identifying and addressing reported vulnerabilities.
    • Validate/ triage the reported vulnerabilities, assess their impact on Singtel’s systems, and collaborate with relevant stakeholders to prioritize and remediate the issues.
    • Track and report on findings and outcomes from the bug bounty program to ensure timely resolution.
    • Develop engaging programs to boost the visibility and popularity of Singtel's bug bounty program.
  • Manage and conduct secure code reviews using scanning tools and techniques to identify security weaknesses in software code.
  • Analyze the results from code scans and work closely with development teams to implement necessary security fixes.
  • Assist in the creation and implementation of secure coding practices across the organization.
  • Vulnerability Retesting and Documentation:
    • Retest security vulnerabilities arising from various sources e.g. Bug Bounty, Penetration testing, etc. after remediation and update reports with the latest results and outcomes.
    • Develop and maintain comprehensive documentation for all vulnerability assessments, secured code reviews and penetration tests, including detailed findings, methodologies, and recommendations for improvements etc.
  • Stay Current with Security Trends and Threats:
    • Continuously monitor the latest security trends, emerging vulnerabilities, and attack techniques to ensure that security testing methodologies and tools remain up-to-date and effective.

Skills for Success:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Attained OSCP or CREST.
  • At least 5 years of experience working in Cyber and Information security field.
  • Solid experience in application security testing, vulnerability assessment, secure code review and penetration testing.
  • Proficiency in performing AI models, API and application security testing using manual techniques, as well as utilizing runtime vulnerability testing tools and/or code review tools.
  • Strong understanding of OWASP Top 10, CWE/SANS Top 25, and other common vulnerability frameworks.
  • Out of which, at least 3 years experience in delivering various AI model, API, application, infrastructure penetration testing, vulnerability assessment and secure code review.
  • Proficiency in performing AI model, API and application security assessment using manual techniques.
  • Proficient in using and managing various security tools and products like Fortify, AppScan, Webinspect, Burp Suite, Nessus, Guardrails AI, Giskard, Moonshot, Deepcheck, Evidently, Pyrit, Adversarial Robustness Toolbox (ART), PyRIT, etc.

Rewards that Go Beyond

  • Full suite of health and wellness benefits.
  • Ongoing training and development programs.
  • Internal mobility opportunities.

Are you ready to say hello to BIG Possibilities?

Take the leap with Singtel to unlock new opportunities and accelerate your growth. Apply now and start your empowering career!

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Data Protection Solutions Senior Analyst, Controls Testing - TikTok Privacy & Security- Singapore

Singapore, Singapore TIKTOK PTE. LTD.

Posted 6 days ago

Job Viewed

Tap Again To Close

Job Description

About TikTok

TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and we also have offices in New York City, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.

Why Join Us

Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.

We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.

Diversity & Inclusion

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

Job Highlights
  • Career growth opportunity
  • Flat organization
  • 100+ mil users
Responsibilities

Team introduction:
TikTok is seeking a highly adaptable and motivated Senior Analyst to bolster our data sovereignty controls testing program. As a key member of our Data Protection Solutions team, you will play a crucial role in ensuring the privacy and security of our regional data by executing on data sovereignty testing strategy and contributing to the improvement of technical controls across prioritized technology solutions.
You will collaborate closely with various teams, including Legal, Global Security, and Security Engineering, to help ensure continued compliance with data privacy regulations and the implementation of robust security measures, in all stages of solution development. This role reports to the Data Sovereignty Solutions Lead within PnS's Data Protection Solutions team.

Responsibilities:

  • Stay up-to-date with evolving data sovereignty and regionalization requirements (e.g., GDPR, cross-border transfer requirements) and translate these requirements into discrete testing procedures, specific to applicable regions and controls
  • Collaborate with engineers and product owners to assess systems in the design stage, providing a testing framework for short and long-term testing of applicable data sovereignty and regionalization controls, bespoke to their technologies
  • After implementation, continue with ongoing testing of applicable data sovereignty and regionalization controls as products and systems expand or mature
  • Where possible, develop automated testing mechanisms to reduce manual effort and increase program maturity in a sustainable manner
Qualifications

Minimum Qualifications:

  • In-depth knowledge of data privacy regulations and standards, such as GDPR, CCPA, or other global data protection laws
  • Strong understanding of:
    Cross-border data transfers
    Data security and data privacy concepts
    Penetration testing or red team exercises
    Data encryption, tokenization, masking, and redaction
  • Strong critical thinking and technical analysis skills to apply to documentation review or testing design
  • Demonstrate ability to quickly assimilate to new knowledge and remain current on new developments in data sovereignty, data regionalization and data privacy

Preferred Qualification:

  • Bachelors’ Degree or industry equivalent work experience
  • Minimum 5 years experience working in cybersecurity, security engineering, or privacy engineering
  • Relevant certifications:
    CIPP/E
    CISSP
  • Understanding of:
    Cloud security and architecture
    Privacy enhancing technologies
    System design and application development practices
    Common testing frameworks, such as the MITRE ATT&CK framework
  • Strong communication skills to collaborate with cross-functional teams (both technical and non-technical), influence without authority, and persuade priorities, objectives, and controls to stakeholders
  • Demonstrated ability to work effectively in environments of ambiguity and constant change
#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Penetration Testing Jobs